A Flurry of New Digital Legislation and Challenges for Organizations
Recently, a flood of legislation has been directed at organizations at the intersection of IT continuity, data, cybersecurity, and free competition. Under the banner of the EU Digital Agenda, the EU is rolling out a wide range of legislation across society. So much so that some laws are being amended even before they take effect. This doesn’t make the puzzle any easier for organizations.
This new legislation brings with it all sorts of new obligations. These new obligations must, of course, be complied with. And in practice, that can lead to quite a few headaches.
New for executives, too?
The new legislation sometimes causes unease among executives. In such cases, it’s wise to take a step back and keep your eye on the ball.
After all, directors have always been expected to have a clear understanding of their organization’s key risks, dependencies, and continuity issues. The Dutch Corporate Governance Code —for larger companies—has for years been based on adequate risk management, internal control, and oversight. And those standards are also trickling down to smaller organizations. Consider, for example, the increasing attention being paid to IT and its manageability in the standards used by auditors.
Governance Increasingly Prominent on the Board Agenda
It is true that, due to all these developments—not only legal but also IT-related—the topic is appearing more explicitly on the board’s agenda. For example, the revised Corporate Governance Code introduces the Statement on Risk Management (VOR). Board members will have to account more explicitly for how they identify, manage, and monitor the company’s risks.
IT is a strategic board topic
And that is precisely why IT is increasingly becoming a topic for the boardroom. After all, anyone who wants to seriously claim in 2026 that the organization is “in control” will also need to be able to address cyber risks, AI applications, cloud dependencies, and digital continuity.
From paper to practice, or from policy to proof
A trend we’re currently seeing among many clients is that the conversation is shifting from policy to demonstrable control. Virtually every organization today has cybersecurity policies, cloud policies, or AI guidelines. But more and more often, the follow-up question arises: Can you also demonstrate that you actually have a firm grip on things?
Take AI, for example. Many organizations now use ChatGPT, Microsoft Copilot, or other AI solutions. Yet executives often struggle to answer a seemingly simple question: “Which AI systems are actually being used within our organization?”
That may seem like an operational question—until it becomes clear that employees may be processing contracts, procurement documents, medical data, financial information, or confidential business information using AI. This immediately turns it into a governance issue.
Furthermore, under the influence of the AI Act, the focus is shifting from experimentation to governance, oversight, and transparency. Organizations must be increasingly able to explain where AI is used and how risks are managed.
1. Does the board have an overview of data and AI?
Boards would be wise to organize answers to four questions before the end of this quarter:
- Which AI systems are being used?
- What data is processed in these systems?
- Which vendors are involved?
- Who oversees these applications?
It is becoming increasingly clear that this information is scattered throughout the organization but is not consolidated at the management level.
This becomes relevant when executives will soon have to demonstrate that risks are actually being managed.
2. Is there really such a thing as digital autonomy?
A second trend we’re seeing is that digital autonomy is becoming less of a political concept and more of a governance issue.
During our executive event on digital autonomy earlier this year, it became clear that many executives aren’t so much concerned with whether they should switch to European technology. Their question is often simpler: Do we actually know how dependent we are?
Which business processes would fail if a cloud provider were to go out of business? What data can we retrieve? What exit rights do we have under our contracts? What alternatives actually exist?
These questions come even before those regarding a potential migration to a European alternative. After all, a migration isn’t something you do “just like that.” And it certainly isn’t always necessary.
Behind the scenes, the EU is actively working—both administratively and politically —on issues such as cloud sovereignty, European AI capacity, and reducing strategic dependencies on non-European technology. However, these are lengthy processes that executives shouldn’t wait for.
Managers who want to issue a credible Statement of Risk (VOR) in the future—or who wish to discuss this with their auditor—can hardly afford to lack insight into their most critical digital dependencies.
Digital autonomy is therefore less and less a technological debate and increasingly a component of risk management.
3. AI: From Innovation to Core Processes
Many organizations are currently still in an experimental AI phase. We expect this to change rapidly over the next six months.
AI is increasingly becoming part of:
- Customer service;
- Software development;
- Document processing;
- HR processes;
- Compliance processes;
- Professional services.
As a result, governance requirements are also changing. After all, the question is not whether AI is being used, but how it is being used and how its use is adequately safeguarded. When AI is integrated into core processes, there is a need for oversight, controls, accountability, and documentation—precisely the issues that ultimately also come into play in risk management and governance.
And the risks that could arise are numerous. For example, previous case law establishes that the response a customer service representative gives to a consumer is, in principle, binding. Applied to AI, this means that a chatbot that gives nonsensical responses could lead to consumer complaints or fines from the ACM (up to 900k or 10% of revenue). Or what about an algorithm in the HR department that turns out to be discriminatory? Or, on a more philosophical note: if all kinds of processes are automated in a self-learning manner, who ultimately retains oversight and control?
For the record: this is not an argument against the use of AI and similar technologies. Certainly not. We use it ourselves. It is, however, a reminder that its use must be well thought out.
4. Cybersecurity in the Boardroom
Perhaps the most visible development is that cybersecurity is becoming less and less of an IT issue.
When a ransomware attack shuts down production, a hospital can’t access patient records, or a service provider can’t serve customers for days on end, it’s no longer about technology. It’s about business continuity.
That is precisely why we’re seeing increasing focus on executive training, crisis drills, and governance requirements under regulations such as NIS2.
The questions board members are increasingly being asked are:
- What is our worst-case digital disaster scenario?
- How long can we continue to operate under those conditions?
- Have we ever practiced that scenario?
- When was the last time the board of directors received a report on this?
What’s interesting is that these aren’t new questions. They’re classic governance questions with a digital twist.
The rules are new, but the board’s responsibility is not
Anyone looking at AI, cybersecurity, cloud sovereignty, and the rapidly growing volume of digital regulations might get the impression that board members are facing an entirely new reality.
That is only partly true.
The underlying standard is remarkably familiar. Directors have always been expected to identify risks, understand dependencies, and safeguard the continuity of their organization. Increasingly far-reaching reporting requirements (such as the VOR, but also consider the regular audit) primarily make that responsibility more visible and concrete.
This also makes it clear that IT is no longer merely a support function. It has become a strategic priority.
After all, anyone who will soon be declaring that the organization has its most significant risks under control will also need to be able to address AI, cybersecurity, cloud dependencies, and digital resilience.
At Dirkzwager, we’ve noticed that many executives, regulators, CIOs, and general counsels are currently grappling with precisely these issues. Based on our practical experience, we regularly assist organizations with digital governance, sourcing issues, AI strategy, cyber resilience, and the design of governance control mechanisms.
The question here is usually not whether technology will become important.
The question is whether the board now has sufficient insight into the risks and dependencies that have come with that technology.